On September 17, 2026, by lifting the injunction against SOLOCAL MARKETING SERVICES, the CNIL closed the case it had opened in 2022, which had resulted in a fine of 900,000 euros for electronic marketing without valid consent based on files purchased from data brokers and other third-party suppliers.
This case brings back responsibility for any company that purchases, rents, or supplements prospecting databases to the forefront of the debate: the use of an initial third-party data collector in no way transfers liability for the validity of consent.
During an investigation into the practices of SOLOCAL MARKETING SERVICES – which purchased prospect data from data brokers, operators of sweepstakes and product testing websites, and then used it for marketing purposes via text message or email on behalf of its advertising clients (or transmitted it directly to them) – the CNIL found the company guilty of two violations:
These forms highlighted – through their size, color, labeling, and placement – the buttons indicating acceptance of the use of data for marketing purposes, while participation in the contest without such acceptance was offered only via simple hyperlinks that were barely visible and blended into the body of the text. The consent thus obtained was neither freely given nor unambiguous.
Furthermore, the contractual requirements imposed by SOLOCAL MARKETING SERVICES on its upstream suppliers, as well as the checks it claimed to carry out downstream, were deemed manifestly insufficient by the CNIL and were therefore not sufficient to rectify this situation.
SOLOCAL MARKETING SERVICES was thus unable to prove the lawfulness of its marketing activities. The CNIL further notes that the company did not immediately suspend processing after discovering that its main partner could not provide proof of consent, and reportedly continued to use the transmitted data to carry out marketing activities for nearly 17 months.
On 15 May 2025, the CNIL therefore ordered SOLOCAL MARKETING SERVICES to pay a fine of 900,000 euros and issued an injunction to cease conducting electronic marketing campaigns without valid consent, subject to a penalty of 10,000 euros per day of delay after a nine-month period.
On 17 September 2026, the CNIL lifted this injunction, as SOLOCAL MARKETING SERVICES had implemented, within the prescribed time limit, measures enabling it to verify the validity of the consent collected on its behalf by its primary data-collecting partners.
These measures are based on an automated analysis of data collection forms, combined with human review and multiple checkpoints: checkbox, information notices, and detection of presentations that could affect the consent of the data subjects.
While the CNIL considers these measures sufficient, it reiterates that SOLOCAL MARKETING SERVICES remains fully responsible for the validity of the consents collected on its behalf and could therefore face penalties in the event of non-compliance related to invalid forms that may have escaped its oversight.
As the legal framework for commercial solicitation becomes stricter – as evidenced by French Law No. 2025-594 of 30 June 2025, which now requires consumers’ prior consent for telemarketing – companies engaging in commercial solicitation using third-party databases must strengthen their controls.
The SOLOCAL MARKETING SERVICES case serves as a reminder to companies that acquire or expand their prospect databases from third parties for marketing purposes that liability does not end with the original data collector.
To ensure that marketing activities comply with the requirements of the GDPR, the CPCE, and the CNIL’s recommendations, there are several key lessons to be learned.
Although the data is initially collected by a third party, the user of the data for marketing and prospecting purposes is responsible for the lawfulness of these operations. The warranty clauses imposed on suppliers do not exempt the user from this responsibility: they may serve as the basis for a recourse action, but not as an acceptable defense before the CNIL.
Pursuant to Article 7 of the GDPR, data controllers who process this data must be able to demonstrate, at any time, that the recipients have given their consent. In the absence of proof, the supplier in question must be immediately suspended.
Finally, since control mechanisms reduce the risk of invalid consent without eliminating it entirely, the user remains liable for non-compliant data collection forms that may have slipped through the cracks. The user must exercise heightened vigilance and regularly monitor its data suppliers.
Therefore, before using any transmitted data:
Then, as part of your prospecting activities:
A prominent button that constitutes acceptance of both the primary data processing and marketing communications, alongside a discreet link to participate without accepting this purpose, invalidates the consent.
Therefore, to ensure that all data collection conducted on your behalf is compliant:
If in doubt, or if a supplier is unable to provide proof of consent from the data subjects, immediately suspend this data source.
If you have any questions or need assistance, please don’t hesitate to contact our IT/Data team!
Jeannie Mongouachon, Partner, and Juliette Lobstein, Associate, at Squair
.png)